Skip to content

Instantly share code, notes, and snippets.

@SansGuidon
Created June 12, 2017 14:50
Show Gist options
  • Save SansGuidon/b7e4487075cdff1592d819a679a32879 to your computer and use it in GitHub Desktop.
Save SansGuidon/b7e4487075cdff1592d819a679a32879 to your computer and use it in GitHub Desktop.
Splunk : use a separator/delimiter for field extraction
host=cbsysstash31 invalid username | eval fields=split(_raw,"|") | eval userid=mvindex(fields,2) |
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment